NOTROBIN is a Linux backdoor associated with opportunistic exploitation of Citrix ADC and Citrix Gateway appliances vulnerable to CVE-2019-19781. It emerged during the large-scale exploitation wave against internet-facing Citrix NetScaler systems and is notable for combining post-exploitation persistence with adversary patching behavior intended to lock out competing intruders. After compromise, operators used NOTROBIN to maintain access on affected appliances and to alter the environment so subsequent exploitation attempts by others would fail. Public reporting has also described the malware removing competing web shells and restricting re-entry to actors possessing the correct secret material, making it both a backdoor and a mechanism for monopolizing compromised hosts.
The malware targets Linux-based Citrix appliance environments rather than desktop Linux systems. Its deployment is tied to direct exploitation of a perimeter-device remote code execution flaw rather than user-driven delivery such as phishing. NOTROBIN has been repeatedly cited as an example of Linux malware spread through vulnerability exploitation on exposed infrastructure. It is also referenced in broader discussions of adversary patching, in which attackers remediate or partially harden the exploited entry point after gaining access in order to reduce competition and complicate defender assessment.
Operationally, NOTROBIN is most closely associated with attacks on enterprise remote access and application delivery infrastructure. The affected systems are high-value because compromise can provide a foothold on critical edge devices used by governments, large enterprises, and other organizations with internet-facing Citrix deployments. High-confidence reporting supports its classification as a Linux backdoor used in post-compromise control and defense-evasion activity following exploitation of CVE-2019-19781.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
As an example, the attacker behind the NOTROBIN backdoor exploited CVE-2019-19781, a vulnerability in Citrix NetScaler, to spread the malware.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Vulnerability exploit: attackers will search for exploitable and unpatched publicly faced components in order to access systems. As an example, the attacker behind the NOTROBIN backdoor exploited CVE-2019-19781, a vulnerability in Citrix NetScaler, to spread the malware.
Attackers can use this functionality to upload/execute command and control (C2) software (webshell or reverse-shell executable) using embedded commands (e.g., curl, wget, Invoke-WebRequest).
A week before the 2019 holidays Citrix announced that an authentication bypass vulnerability was discovered in multiple Citrix products... Exploiting the vulnerability could allow an unauthenticated attacker to perform arbitrary code execution on the Citrix appliance.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware/threat name mentioned only as historical context because infrastructure overlapped with an IP previously associated with attacks on Citrix servers.
Mentioned as an example of ELF malware written in Golang.
Backdoor spread by exploiting a Citrix NetScaler vulnerability.
Backdoor observed in the Citrix NetScaler/ADC CVE-2019-19781 exploitation wave; removes competing webshells and modifies components to allow only the operator (with a secret key) to re-enter, leaving systems appearing patched but still compromised.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.